Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
The Department of Commerce's International Trade Administration published a Federal Register notice on 10 April 2026 (91 FR 18412, doc 2026-06952) opening the inaugural Call for Proposals for the American AI Exports Program established under Executive Order 14320. Proposals are accepted from 1 April 2026 through 5:00 pm EDT on 30 June 2026 from US industry-led "pre-set" consortia offering full-stack American AI export packages — AI-optimised hardware, data pipelines, AI models and systems, security and cybersecurity measures, and sector-specific applications — for presentation by the US government to foreign public- and private-sector buyers. Designated consortia receive priority US-government advocacy, priority consideration for export-control licence engagement, interagency coordination, and federal-financing referrals (EXIM, DFC), with a 14-business-day completeness review and 60-calendar-day designation decision once a proposal is deemed complete.
On 31 March 2026 the Government of Vietnam issued Decree 96/2026/ND-CP, the principal implementing decree for the Law on Investment 2025 (Law 143/2025/QH15). It takes effect on its signing date and replaces Decree 31/2021/ND-CP, Decree 19/2025/ND-CP and Decree 239/2025/ND-CP — the first comprehensive overhaul of Vietnam's general FDI-licensing framework since 2021. The decree operationalises the new Special Investment Procedure (a registration-and-commitment fast-track in industrial parks, export-processing zones, hi-tech parks, concentrated digital- technology zones, free-trade zones, international financial centres and economic-zone functional areas) and details the list of 16 specially-incentivised sectors covering semiconductor and chip manufacturing, AI, big data, digital technology and high-tech R&D. It also rewrites foreign-investor market-access conditions, document procedures and dispute / grievance mechanisms.
President Trump signed Executive Order "Ending Certain Tariff Actions" on 20 February 2026 (Federal Register doc 2026-03832, published 25 February 2026), terminating the additional ad-valorem duties imposed under nine prior IEEPA-based executive orders. The order followed within hours of the US Supreme Court's 6-3 decision the same day in Learning Resources, Inc. v. Trump, 607 U.S. ___ (2026), holding that the International Emergency Economic Powers Act does not authorize the President to impose tariffs and vacating the Trump 2.0 IEEPA tariff regime. The EO directs CBP to cease collection "as soon as practicable"; CSMS guidance set the collection-end date at 12:00 a.m. eastern on 24 February 2026. The order explicitly preserves all underlying national-emergency declarations and all non-IEEPA trade actions — Section 232 of the Trade Expansion Act, Section 301 of the Trade Act, Section 122 of the Trade Act, and Section 201 — so the Section 232 cascade and the paired Section 122 10% temporary surcharge (effective 24 Feb 2026) remain in force. This is the first SCOTUS-driven repeal of a presidential tariff regime in the modern era and recalibrates the entire post-2024 US tariff architecture by removing IEEPA as a legal pillar.
President Trump signed a Presidential Proclamation on 20 February 2026 invoking Section 122 of the Trade Act of 1974 (19 U.S.C. § 2132) to impose a temporary 10% ad-valorem import surcharge on articles imported into the United States, effective 12:01 a.m. EST on 24 February 2026. The proclamation was issued within hours of the US Supreme Court's 20 February 2026 ruling in Learning Resources, Inc. v. Trump, which held that the International Emergency Economic Powers Act (IEEPA) does not authorize the president to set tariffs and vacated the IEEPA-based reciprocal-tariff regime previously in effect. The Section 122 surcharge is statutorily limited to 150 days (terminates 24 July 2026 absent Congressional extension) and the statute caps any such surcharge at 15% ad valorem. Goods qualifying as USMCA originating from Canada or Mexico are exempt; CAFTA-DR textile/apparel articles meeting specified rules of origin are exempt; and a substantial product-exception list excludes critical minerals, energy products, certain pharmaceuticals, electronics, vehicles, aerospace products, specified agricultural goods, and goods already subject to Section 232 duties (the Section 122 duty does not stack on Section 232).
Presidential Decision No. 10767, published in the Official Gazette (Resmî Gazete, Issue No. 33118) on 25 December 2025, re-sets the Digital Services Tax (Dijital Hizmet Vergisi, DHV) rate under Article 5(3) of Law No. 7194. The rate, set at 7.5% since the tax's 2020 introduction, is reduced to 5% for revenue generated from 1 January 2026 and to 2.5% for revenue generated from 1 January 2027. The tax applies to gross Turkish-sourced revenue of digital-service providers (online advertising, content sales, social-media/intermediary platforms) exceeding statutory turnover thresholds, and falls predominantly on large non-resident platform operators (Google, Meta, Amazon and comparable multinationals).
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
India's Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 via Gazette notification G.S.R. 846(E) on 13 November 2025, operationalising the 2023 DPDP Act. The Rules introduce a "negative list" cross-border personal-data transfer regime under Rule 14, verifiable parental consent, breach-notification windows, and tiered penalties up to INR 250 crore. Implementation is phased: Data Protection Board provisions in force on notification, Consent Manager rules from 13 Nov 2026, and core data-fiduciary / cross-border-transfer obligations from 13 May 2027.
Germany's transposition of EU Directive 2022/2555 (NIS2), enacted as the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung." Bundestag passage 13 November 2025; Bundesrat approval 21 November 2025; published as BGBl. I 2025 Nr. 301 on 5 December 2025; entered into force 6 December 2025. The statute designates the Bundesamt für Sicherheit in der Informationstechnik (BSI) as the central national supervisory authority over an estimated 29,500 covered entities across 18 critical and important sectors, introduces a mandatory 24h initial / 72h detailed / 1-month final cyber-incident reporting cascade, establishes board-level personal liability for senior management, and applies to SME critical- infrastructure suppliers — with no transitional grace period from entry into force.
On 18 September 2025 Brazil's federal government published Medida Provisória (Provisional Measure) 1318/2025, creating REDATA — the Special Taxation Regime for Datacenter Services — alongside a parallel IT-export regime (REPES). REDATA zeroes federal taxes on servers, storage, networking, cooling and other datacenter capital equipment for qualifying operators from 1 January 2026, conditioned on 100% renewable/zero-carbon energy sourcing, a 2% of investment R&D-in-Brazil commitment, and preferential use of Brazilian- manufactured components. The Finance Ministry projects R$5.2 billion in forgone-tax incentives in 2026 alone, with potential to unlock up to R$2 trillion in private datacenter investment over ten years. REDATA is framed as implementing the National Datacenter Policy (PNDC) under the Nova Indústria Brasil industrial-policy umbrella.
The FCC adopted a Report and Order (FCC 25-49) on 7 August 2025 — the first comprehensive overhaul of submarine cable landing license rules since 2001 — effective 26 November 2025. The order prohibits Indefeasible Right of Use (IRU) agreements that would give entities from designated foreign adversary countries (China including Hong Kong and Macau, Cuba, Iran, DPRK, Russia, and Venezuela) control over Submarine Line Terminal Equipment (SLTE) on US cable landings, and mandates new annual reporting plus certification/disclosure requirements covering ownership, cybersecurity and physical security plans, and FCC Covered List compliance. The order operationalises the FCC's bifurcated policy package: accelerating legitimate commercial cable buildout while hardening national-security review for foreign-adversary-connected infrastructure.
Canada announced on 29 June 2025 that it would rescind the Digital Services Tax Act (originally enacted 20 June 2024) to revive US-Canada trade negotiations after President Trump suspended talks on 27 June, citing the 3% DST on large digital-services revenues as a discriminatory measure against US technology firms. The Canada Revenue Agency halted collection effective 30 June 2025, and legislation to retroactively repeal the Act back to its June 2024 enactment date is to follow, with refunds — plus interest at the standard corporate tax refund rate — to be paid to affected taxpayers including US technology majors.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
On 13 May 2025, two days before the AI Diffusion Rule's primary 15 May 2025 compliance date, the Trump administration's BIS announced it would rescind the Biden-era Framework for AI Diffusion (90 FR 4544) and simultaneously issued three guidance documents that re-routed US AI export policy through existing EAR authorities. The package comprises (1) GP10 guidance asserting that all ECCN 3A090 ICs designed by PRC-headquartered firms are presumptively EAR-violative, with Huawei Ascend 910B/910C/910D processors named explicitly — making US- and non-US-person use, transfer, financing, or servicing of those chips anywhere in the world a presumptive General Prohibition 10 violation; (2) a policy statement warning industry that supplying US advanced computing ICs for training or inference of Chinese AI models risks EAR enforcement; and (3) industry guidance on diversion-prevention diligence. BIS stated a formal Federal Register rescission and replacement rule would follow.
On 9 April 2025 the European Commission adopted Communication COM(2025)165, the AI Continent Action Plan, setting out a five-pillar strategy to make the EU a global AI leader. The pillars are (1) computing infrastructure, (2) data for AI, (3) strategic AI innovation and adoption, (4) AI skills and talent, and (5) regulatory simplification. Headline commitments include mobilising approximately €200bn of public+private investment via the InvestAI initiative announced at the AI Action Summit in Paris (11 February 2025), deploying 13 AI Factories (HPC-anchored shared compute facilities) plus regional antennas, building 5 AI Gigafactories powered by >100,000 advanced AI processors with €20bn earmarked from InvestAI, launching the Apply AI Strategy and Data Union Strategy, and proposing a Cloud and AI Development Act with a public consultation closing 4 June 2025. The one-year progress report (9 April 2026) confirmed 19 AI Factories deployed across EU supercomputers with 13 Antennas providing regional access, and €1bn in Apply AI funding calls earmarked.
President Trump signed Executive Order 14257 on 2 April 2025 declaring a national emergency over US trade deficits and imposing a baseline 10% ad-valorem tariff on imports from nearly all trading partners effective 5 April, with higher country-specific "reciprocal" rates effective 9 April. The rate schedule was constructed from a formula tied to bilateral goods-trade deficits and ranged from 10% (UK, Singapore, Brazil, Australia, others) through 20% (EU), 24% (Japan), 25% (Korea), 32% (Taiwan, Indonesia, Switzerland), 34% (China, later raised to 84% then 125% during the April escalation), 46% (Vietnam), 49% (Cambodia). Multiple subsequent EOs paused the country-specific rates for 90 days for non-China destinations on 9 April while keeping the 10% baseline, pending bilateral negotiations.
Commission Delegated Regulation (EU) 2025/532, adopted 24 March 2025 and published in the Official Journal on 2 July 2025, supplements DORA (Regulation (EU) 2022/2554) with binding Regulatory Technical Standards governing ICT subcontracting of critical or important functions. It requires all EU-regulated financial entities to establish a subcontracting policy, conduct due-diligence and concentration-risk assessments at each tier of the ICT supply chain (including nth-party providers), impose equivalent resilience standards on sub-ICT-providers, and maintain enforceable termination and information-access rights. The RTS entered into force on 22 July 2025, completing the second-batch DORA implementing acts on outsourcing chains.
The Nigeria Data Protection Commission issued the General Application and Implementation Directive (GAID) 2025 on 20 March 2025, the principal implementing directive of the Nigeria Data Protection Act 2023 (NDPA). The GAID came fully into force on 19 September 2025, replacing the Nigeria Data Protection Regulation (NDPR) 2019 as the operative enforcement instrument. It applies extraterritorially to any data controller or processor established outside Nigeria that processes personal data of Nigerian data subjects, imposes a tripartite cross-border transfer framework (adequacy decisions, Transfer Instruments, and statutory exceptions), mandates Data Protection Impact Assessments for AI and high-risk technologies, and carries a civil-penalty ceiling of 2% of annual gross revenue or NGN 10 million for designated data controllers and processors of major importance (DCPMIs), whichever is greater.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
President Trump signed Executive Order 14179 on 23 January 2025 (published in the Federal Register on 31 January 2025 as 90 FR 8741, doc 2025-02172). The order revokes Biden-era Executive Order 14110 of 30 October 2023 ("Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence") and directs federal agencies to identify and rescind, revise, or suspend any policies, regulations, memoranda, or guidance documents adopted pursuant to the revoked Biden order. It mandates that the Assistant to the President for Science and Technology, the Assistant to the President for National Security Affairs, the Special Advisor for AI and Crypto, and the Assistant to the President for Economic Policy develop an AI Action Plan within 180 days to "sustain and enhance America's global AI dominance." The plan was released on 23 July 2025. EO 14179 reframes US AI industrial-policy posture from safety-first regulation to deregulation, infrastructure investment, and export-competitiveness.
The UK government published the AI Opportunities Action Plan (CP 1241) on 13 January 2025, authored by Matt Clifford CBE (Chair, ARIA), and simultaneously accepted all 50 recommendations via the government response (CP 1242). The plan establishes binding cross-government commitments including a 20× expansion of UK sovereign AI compute capacity by 2030, designation of AI Growth Zones (Culham, Oxfordshire named first), a National Data Library, and energy-grid prioritisation for AI datacentres. It positions AI compute as critical national infrastructure and represents the most comprehensive national AI industrial-policy roadmap published in the UK to date.
The Bureau of Industry and Security signed an Interim Final Rule on 13 January 2025 (90 FR 4544, published 15 January 2025) introducing the first horizontal export-control regime for advanced AI compute and closed-weight model weights. It revised ECCN 3A090 advanced-IC thresholds, created a new ECCN 4E091 covering closed-weight model weights trained on more than 10^26 operations, and bucketed every destination worldwide into a three-tier country group: Tier 1 (~18 close allies, license-free flows), Tier 2 (the rest of the world, per-country compute caps with National VEU and Universal VEU pathways), Tier 3 (US arms-embargoed destinations including China and Russia under comprehensive denial). It added license exceptions AIA, ACM, and LPP and set staggered compliance dates of 15 May 2025 (general) and 15 January 2026 (data-center / model-weight provisions). The Trump administration's BIS rescinded the rule on 13 May 2025 — two days before the primary compliance date — but it was on the books for four months and shaped allied compliance build-out and the architecture of subsequent US AI export controls.
Bolivia's Decreto Supremo 5309, signed by President Luis Arce on 8 January 2025, mandates that all public-sector entities migrate their information systems to Free Software and Open Standards by 12 January 2030. The decree includes a data-localization provision barring storage of non-public state data on servers outside Bolivian territory; government cloud workloads must run either on public-entity infrastructure or on state-operated cloud services within the country. AGETIC (Bolivia's ICT agency) is responsible for overseeing compliance and developing the implementation plan (approved via the companion Decreto Supremo 5322 on 23 January 2025).
The Republic of Korea's National Assembly passed the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness ("AI Basic Act") in plenary session on 26 December 2024, consolidating 19 separate AI bills tabled in the 22nd National Assembly. The statute was promulgated on 21 January 2025 and takes effect on 22 January 2026 after a one-year preparation period. Korea becomes the second jurisdiction worldwide — after the EU AI Act — to enact a comprehensive horizontal AI law, and the first in the Asia-Pacific. The Act establishes a risk-tiered regime targeting "high-impact" AI in healthcare, energy, public services, employment decisions, and generative-AI labelling, with extraterritorial reach over foreign providers whose systems affect the Korean market or users (mandatory local representative). It creates an AI Safety Institute, a national AI policy "control tower," and R&D / standardisation programmes under MSIT. Penalties are modest by international comparison — fines up to KRW 30 million plus a one-year grace period before full enforcement.
Regulation (EU) 2025/40, published in the Official Journal on 22 January 2025 and entering into force on 11 February 2025, replaces the 1994 Packaging and Packaging Waste Directive 94/62/EC with a directly-applicable Regulation. It mandates binding recycled-content targets for plastic packaging (by polymer and format, reaching 30–65% by 2030 with higher targets by 2040), minimum reusable-packaging shares for beverages and transport, recyclability standards for all packaging placed on the EU market from 2030, deposit-return-scheme obligations for beverage containers from 2029, and bans on specified single-use plastic packaging formats. General application begins 12 August 2026, with staggered compliance windows extending to 2030 and beyond, affecting all non-EU exporters shipping consumer goods, beverages, or e-commerce fulfilment into the EU single market.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
India's Finance (No. 2) Act, 2024 (Act No. 15 of 2024) repeals the 2% Equalisation Levy on e-commerce supplies and services by non-resident operators (§165A of the Finance Act 2016, introduced 2020), with effect from 1 August 2024. The repeal removes a long-standing US trade irritant — the USTR had found the 2% levy unreasonable under a Section 301 investigation, and India agreed in October 2021 to remove it as part of a multilateral OECD Pillar 1 commitment, formally implemented here three years later. The residual 6% Equalisation Levy on digital advertising under §165 (in force since 2016) was not touched by this Act and remained in force until its own repeal effective 1 April 2025 via a subsequent Finance Act.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
The Indiana Economic Development Corporation approved up to USD 18.3 million in EDGE (Economic Development for a Growing Economy) payroll-based tax credits for Amazon Data Services Inc., tied to Amazon Web Services' USD 11 billion data center campus at the Indiana Enterprise Center in New Carlisle, St. Joseph County. The credit was one component of a larger state incentive package announced by Governor Eric Holcomb on 2024-04-25, which also included up to USD 55 million in Hoosier Business Investment tax credits, up to USD 20 million in redevelopment tax credits, up to USD 5 million in training grants, a USD 7 million road-infrastructure contribution, and a 50-year state sales-tax exemption on data center equipment. IEDC records cite an incentive-agreement effective date of 2023-09-01. The project committed to creating at least 1,000 new jobs.
The Indiana Economic Development Corporation approved up to USD 55 million in Hoosier Business Investment (HBI) tax credits for Amazon Data Services Inc., tied to Amazon Web Services' USD 11 billion data center campus at the Indiana Enterprise Center in New Carlisle, St. Joseph County. This is the largest single instrument in the five-part state incentive package Governor Eric Holcomb announced on 2024-04-25, which also included up to USD 18.3 million in EDGE payroll tax credits, up to USD 20 million in redevelopment tax credits, up to USD 5 million in training grants, a USD 7 million road-infrastructure contribution, and a 50-year state sales-tax exemption on data center equipment. IEDC describes all incentives as performance-based, claimable only once the underlying investment and job-creation commitments are verified. IEDC records cite an incentive-agreement effective date of 2023-09-01.
The Indiana Economic Development Corporation approved up to USD 20 million in redevelopment tax credits for Amazon Data Services Inc., tied to Amazon Web Services' USD 11 billion data center campus at the Indiana Enterprise Center in New Carlisle, St. Joseph County. This is the third of five distinct incentive instruments in the state package Governor Eric Holcomb announced on 2024-04-25, alongside up to USD 18.3 million in EDGE payroll tax credits, up to USD 55 million in Hoosier Business Investment tax credits, up to USD 5 million in training grants, a USD 7 million road-infrastructure contribution, and a 50-year state sales-tax exemption on data center equipment. IEDC records cite an incentive-agreement effective date of 2023-09-01.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
Ireland's Screening of Third Country Transactions Act 2023 (Act No. 28 of 2023), signed into law on 31 October 2023 and commenced on 6 January 2025 via S.I. No. 651 of 2024, establishes Ireland's first-ever mandatory inbound FDI screening regime. The Act empowers the Minister for Enterprise, Tourism and Employment to assess, condition, or prohibit transactions by third-country investors (non-EU/EEA/Switzerland) exceeding a EUR 2 million cumulative threshold in targets operating across critical infrastructure, critical technologies, dual-use items, supply of critical inputs, sensitive personal data, and media freedom. A 90-day standstill period applies during Ministerial determination, with criminal sanctions and transaction-voiding powers available for non-compliance.
Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act, DSA) was adopted by the European Parliament and Council on 19 October 2022, published in OJ L 277 on 27 October 2022, entered into force on 16 November 2022, and applied in full from 17 February 2024 (with VLOP/VLOSE obligations applying from 25 August 2023 following the Commission's initial designation letters of February 2023). The DSA establishes a graduated intermediary-liability and platform-safety framework covering all online intermediaries serving EU users, with the heaviest obligations falling on designated Very Large Online Platforms (VLOPs, ≥45m monthly active EU users) and Very Large Online Search Engines (VLOSEs): systemic-risk assessments, annual independent audits, vetted-researcher data access, recommender-system transparency, online-advertising transparency, and crisis-response cooperation mechanisms under Commission coordination. The European Commission holds exclusive enforcement authority over VLOPs and VLOSEs, with fines up to 6% of global turnover. The DSA is the structural twin-pillar to the Digital Markets Act (Reg (EU) 2022/1925): the DMA governs ex-ante competition obligations on designated gatekeepers; the DSA governs ex-post intermediary-liability, content-moderation, and platform-safety obligations across all online intermediaries.
Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act, DMA) was published in OJ L 265 on 12 October 2022, entered into force on 1 November 2022, and applied for the most part from 2 May 2023. The DMA establishes an ex-ante competition framework imposing binding obligations and prohibitions on designated "gatekeepers" operating Core Platform Services (CPS) in the EU — covering search engines, social-networking services, video-sharing platforms, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, online intermediation services, and online advertising. The European Commission designated six gatekeepers on 6 September 2023 (Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft); full compliance with all obligations was required by 7 March 2024. Subsequent designations added Booking.com (May 2024) and Apple iPadOS (April 2024). The DMA functions as the EU's structural anchor for ex-ante digital competition regulation, closing the enforcement gap left by ex-post competition law (Articles 101–102 TFEU) where market-tipping dynamics make remedies ineffective after the fact.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.